Cloudless Voice runs entirely on your device. No cloud. No remote servers. This page explains exactly what that means for your data — and, for security reviewers, how the software is built, shipped, and run inside your environment.
TL;DR
Audio and transcripts are processed locally and never leave the device.
Only app updates and anonymized crash diagnostics use the network; your content never does.
Usage analytics are opt‑in on macOS and iOS, but are not present in Windows or enterprise builds.
Your data is never used to train anyone else’s model
Export or permanently delete your data anytime


Security
Security without badges
Certifications like SOC 2 exist to audit how a company protects data flowing through its servers. Cloudless Voice doesn’t have that server. Your audio is processed entirely on your computer or phone and never transmitted anywhere. This means:
No database to breach
No API handling your transcripts
No server-side infrastructure in the threat model these certifications are built to check
Everything runs on your device
Speech-to-text runs locally on your device using on‑device models. After transcription, a small local model handles post‑processing, including Smart Cleanup. Your computer or phone does the work, and if you’re offline, Cloudless Voice still works. On Mac/iOS, the default model downloads during first setup, and additional models can be added from Settings via Hugging Face. The Windows enterprise build includes its model in the installer, requires no downloads, and disables model switching.
What touches the network
Cloudless’ outbound connections, include update checks, de‑identified crash diagnostics, Mac/iOS model downloads, opt‑in usage analytics, and opt‑in correction submissions. They never carry your audio, transcripts, or any dictated content.
Built, signed & shipped
Opt in
SSO Planned
Publisher: Synthetic Exploration, Inc., which markets its products as Cloudless. MacOS builds are signed with an Apple Developer ID and notarized by Apple. Windows builds are Authenticode-signed. Windows is distributed as a signed MSI for managed deployment and a signed .exe for individuals; Mac is distributed as a signed .dmg.
Updates, patching & deployment
Cloudless Voice ships signed updates through the app, signature-verified before install. Managed and enterprise teams can control or disable the update schedule and deploy new versions via MDM/RMM. Cloudless Voice is built to slot into a managed fleet with minimal review surface: signed MSI, IT-controlled updates, EDR-friendly signing, microphone permission for local audio processing, and Accessibility permission used to insert dictated text into the focused field.
Privacy
Analytics
Mac/iOS individual app
Not in the Windows build
On the Mac/iOS individual app, we collect basic usage analytics: the features you use, not what you say. We collect analytics via PostHog, linked to your email if you use an account. This helps us prioritize and detect issues. Opt out anytime. The Windows build has no analytics at all.
Requesting a transcript fix
Mac/iOS individual app
Not in the Windows build
On Mac/iOS you can manually send a specific clip from the correction flow so we can fix a mistake. This only happens when you choose to share it, never automatic. This flow does not exist in the Windows build.
Export
Export your transcripts from Settings anytime.
Delete forever
Deleting a transcript removes it permanently from your device. There’s no remote copy. You can also opt out of saving transcripts entirely.
Read the full Privacy Policy →
GDPR
Synthetic Exploration, Inc. (Cloudless) is a Delaware corporation headquartered at 1301 Sansome Street, San Francisco, CA 94133. Because transcription happens entirely on your device, little to no personal data is transmitted to or processed on our servers during normal use, which significantly limits our footprint as a data processor. For analytics and correction-flow submissions, both disabled for Enterprise, we act as the data controller. You can request access to, export of, or deletion of your data, most of which you can already do yourself in-app. Contact us to discuss a DPA.
The third-party services Cloudless Voice relies on, and which build uses each. The Windows enterprise build uses only two — update hosting and crash diagnostics — and neither carries your content.
Microsoft Azure
Hosts the app installer, updates, and Mac model files. Azure receives download requests, including IP and connection metadata. Used by Windows enterprise and Mac/iOS individual builds.
Sentry
Provides crash diagnostics on windows. Sentry sees de-identified crash data, never audio or transcripts. Used by both Windows enterprise and Mac/iOS individual builds, and can be disabled.
Hugging Face
Serves on-device model downloads and sees model-file download requests. Not used by the Windows enterprise build because its model is bundled; used by Mac/iOS.
PostHog
Provides usage analytics. Sees feature-usage events plus email if you have an account. Not present in the Windows enterprise build; opt-out available on Mac/iOS.
Provides optional Google Sign-in and sees account email. Not used by the Windows enterprise build; used on Mac only if you create an account.
Postmark
Sends magic-link login emails and sees account email. Not used by the Windows enterprise build; used on Mac only if you create an account.
Firebase
Stores opt-in correction submissions and sees the clip you choose to send to us on MacOS. Not used by the Windows enterprise build; used on Mac/iOS only when you request a fix on a transcript.
None of these ever receive your audio or transcripts. The only exception is if you manually choose to submit clip for correction on Mac. This list is current as of July 2026; we’ll keep it updated as it changes.
Frequent questions
Do my recordings and transcripts ever leave my device?
No — by default, everything stays on the device it was created on. The one exception is a correction request you manually submit, which sends just that specific clip.
What security certifications do you have?
None yet — by design, not by gap. SOC 2 and similar audit how a company protects data flowing through its servers, and Cloudless Voice doesn’t have a server in that loop. As we build enterprise infrastructure, we’ll pursue the certifications relevant to it.
Are you HIPAA compliant?
Not yet, and we won’t claim it until it’s formally in place. Local processing removes much of the risk HIPAA is designed to manage, because there is no PHI on our servers, but it’s a checklist we’d walk through with you directly — reach out if it’s a requirement.
Do you collect analytics?
For individuals, yes: feature usage, not content, via PostHog, with opt-out anytime. For Enterprise, no.
Do you sell any data?
No. We never sell, rent, or share your data with third parties.
Do you train any models with my data?
Only your local model — your usage improves the model on your device, never a shared or remote model.
